Since 1 September 2023, the revised Federal Act on Data Protection (nFADP) has governed how every Swiss company collects and uses personal data. In 2026, the adjustment period is over: the Federal Data Protection and Information Commissioner (FDPIC) investigates complaints, and an intentional violation exposes the person responsible to a fine of up to CHF 250,000. Yet many SMEs in French-speaking Switzerland are still flying blind: a cookie banner copied from a French website, newsletters sent to old contacts who never gave consent, forms that hoover up more data than necessary.
The good news: bringing a typical marketing setup into compliance — website, newsletter, online advertising — takes a few days of work, not a few months. Here is what the law actually requires for your newsletters, cookies, forms and tracking, followed by a checklist you can implement without a lawyer.
The nFADP in a Nutshell: What Affects Your Marketing
The nFADP protects the data of natural persons: first name, email address, IP address, browsing behaviour, purchase history. As soon as a marketing tool touches any of this information, the law applies. Three principles underpin everything else:
- Transparency: you must clearly inform people about what you collect, why, and who you share it with — that is the role of your website's privacy statement.
- Proportionality: you only collect the data necessary for the stated purpose. A quote request form does not need a date of birth.
- Security: data must be protected technically and organisationally, and breaches presenting a high risk must be reported to the FDPIC.
Unlike the European GDPR, the nFADP does not provide for fines calculated as a percentage of turnover and does not require SMEs to appoint a data protection officer. The record of processing activities is even optional below 250 employees, except for high-risk processing. However, if you actively target customers in the European Union — deliveries to neighbouring France, campaigns in Lyon or Annecy — the GDPR applies on top of Swiss law.
Newsletters: Consent Comes First
Sending commercial newsletters is governed by two pieces of legislation: the nFADP for the data, and the Unfair Competition Act (UCA) for the mass advertising email itself. In practice, three cumulative conditions apply:
- Prior consent (opt-in): the person ticked a box or confirmed a subscription. A pre-ticked box counts for nothing, and neither does a purchased address list.
- An identifiable sender: your company name and a valid contact address in every mailing.
- A working unsubscribe link in every email, effective immediately and free of charge.
There is a valuable exception for SMEs: your existing customers may receive offers for products or services similar to those they have already purchased, without a new opt-in, provided they were able to refuse when their address was collected. A garage in Nyon can write to its customers about tyre changes; it cannot rent its list to an insurer.
A concrete example: a database of 5,000 "legacy" contacts with no proof of consent is a liability, not an asset. A re-permission campaign — an email asking people to confirm their subscription — typically retains 15 to 30% of the list, i.e. 750 to 1,500 genuinely engaged contacts. The rest were not opening your emails anyway.
Cookies and Tracking: What Swiss Law Actually Requires
This is the most misunderstood point. Swiss law does not impose the blocking, European-style consent banner: the Telecommunications Act requires you to inform visitors about the processing — via the privacy statement — and to tell them how to refuse it. A 100% Swiss SME can therefore legally operate with an information banner and an opt-out option.
Be careful, however, with three situations that raise the bar:
- A targeted European audience: the GDPR then requires explicit consent before any non-essential cookie — a banner with equivalent "Accept" and "Refuse" buttons becomes necessary.
- Advertising tools: the Meta pixel, Google Ads tag and remarketing lists create profiles. The nFADP strictly regulates high-risk profiling; to be safe, make these tags conditional on consent. That is the default setup for our Google Ads campaigns in Geneva.
- Transfers outside Switzerland: Google Analytics and Meta transfer data to the United States. This is lawful when the provider is certified under the Swiss-U.S. Data Privacy Framework — check the certification and mention the transfer in your privacy statement.
In practice, a consent management platform (CMP) suited to an SME website costs between CHF 0 and 30 per month and settles the matter: a compliant banner, advertising tags blocked before consent, and a time-stamped proof log.
Forms: Minimise, Inform, Secure
Every form on your website is a collection point subject to the nFADP. Three reflexes:
- Minimisation: only ask for what you need in order to respond. Name, email and message are enough for a contact form — every superfluous field also hurts your conversion rate.
- Information at the point of collection: a link to the privacy statement below the submit button. If the form also feeds your newsletter, add a separate checkbox, never pre-ticked.
- Security: HTTPS is mandatory, and data must be sent to a professional mailbox — not to an employee's personal Gmail account.
During a redesign or a website creation project in Geneva, building these requirements in from the start costs nothing extra; retrofitting them onto a poorly built site quickly runs to CHF 1,000 to 2,000.
Discover our services · Chat on WhatsApp
The Compliance Checklist, No Lawyer Required
Here is the full journey, in order. Allow one to two days of work for an SME with a showcase website and a newsletter:
- Map your data (2 hrs): list where customer data lives — CRM, emailing tool, Google Analytics, Excel files, point-of-sale system. For each source: which data, what purpose, which provider, which country.
- Write or update your privacy statement (3 hrs): identity of the controller, data collected, purposes, recipients, transfers abroad, individuals' rights, contact address. Free Swiss generators provide a solid basis to adapt.
- Run a cookie scan (1 hr): a free analysis tool lists the cookies your site actually sets. Remove unused tags — most websites drag several around.
- Install a CMP (2 hrs): a compliant banner, advertising tags blocked before consent, time-stamped proof of choices.
- Clean up your newsletter list (2 hrs): segment the contacts with proof of opt-in, run a re-permission campaign for the others, delete unreachable addresses.
- Check your processors (1 hr): hosting provider, emailing platform, CRM — each must offer a data processing agreement and, for US providers, certification under the Data Privacy Framework.
- Prepare your access request procedure (1 hr): anyone can ask what data you hold about them; you have 30 days to respond, free of charge. A response template and a designated person are enough.
Bonus point: access requests and data inventories lend themselves very well to AI automation — extracting a contact's data across all your tools then takes a few minutes instead of half a day of manual work.
What Compliance Costs — and What Non-Compliance Costs
For a typical SME in French-speaking Switzerland, with a showcase website, a 3,000-contact newsletter and some online advertising:
- A privacy statement adapted to Swiss law: CHF 0 doing it yourself with a generator, CHF 500 to 900 if outsourced.
- CMP and tag configuration: CHF 0 to 30 per month, plus CHF 300 to 600 for the initial setup.
- Emailing list clean-up: a few internal hours, generally with no paid tooling.
A realistic total: under CHF 2,000 if you outsource everything, close to zero in-house. On the other side of the ledger: a fine of up to CHF 250,000 for intentional violations, the cost of a dispute, and above all the lost trust of customers who pay ever closer attention to how their data is used.
The Three Costly Mistakes
- Copying the privacy policy of a French website: it cites the GDPR and the CNIL, ignores the FDPIC and Swiss law, and commits you to obligations you do not meet. An inaccurate document is worse than an imperfect one.
- Buying address lists: no valid consent covers you, and spam complaints are the main gateway to regulatory scrutiny.
- Running advertising campaigns without gating your pixels: remarketing without consent exposes you legally and skews your measurement data in the process.
Conclusion: Compliance as a Commercial Advantage
The nFADP is not an obstacle to digital marketing; it is a quality filter. An engaged opt-in list performs better, clean tracking measures better, a transparent website converts better. SMEs that demonstrate serious data governance turn a legal constraint into an argument for trust.
At Digital Swiss Agency, every website, campaign and newsletter we deliver builds these requirements in from day one. Tell us about your current setup: a quick audit is usually enough to identify the two or three priority fixes.